Modeling Security
Bart Mennink · 2023
This chapter is concerned with how to formalize security of cryptographic primitives. It presents stream ciphers as a running example and focuses on block ciphers. In general, when evaluating a cipher, one assumes the most powerful adversary model. If it is secure in that model, it is also secure in many weaker models. A random oracle is an ideal cryptographic primitive that generates a random response to each query. The description of distinguishing advantages is for functions that should behave like a random oracle. The claim on advanced encryption standard (AES) turns out to be very useful for claiming security of cryptographic schemes that are built on top of AES. Many cryptographic encryption and authentication schemes used in practice can be considered to be built as modes ofuse on top of AES. Under the assumption that AES is secure, one can abstract this cryptographic primitive and focus on the mode of use itself.